[C++] Solution at the duplication ikarus offline shop + how to duplicate (only for demonstration)

  • Konbuyu başlatan Konbuyu başlatan Admin
  • Başlangıç tarihi Başlangıç tarihi
  • Cevaplar Cevaplar 0
  • Görüntüleme Görüntüleme 104

Admin

Metin2Lobby
Yönetici
Founder
Katılım
6 Mayıs 2022
Mesajlar
52,647
Ticaret : 1 / 0 / 0
Hello everyone, since no one talks about it and many no longer receive answers from ikarus despite having bought his offline store like me, today I want to share with you completely free one of the fix methods I have thought of to prevent duplication via safebox (I'm sure it's not the best way to fix it but with this you prevent any duplication via safebox 100%).
First of all I want to show you the method of how to do the duplication, I state that I only discovered it after various tests / attempts and lost hours (I asked people who knew the bug but they did not want to show me how to do it, even someone was selling for euro the tutorial, so I wondered why not find out for myself?).

(The video I am about to show you is for demonstration purposes only and I release myself from any responsibility in this regard)



How does duplication actually work? Simply put, through a series of logout and login in different cores / channels to be able to split the item and have both in core1 / core2 or ch1 / ch2 just like in the video you saw previously. To avoid this we will ensure that it will be possible to withdraw the items / yangs from your safebox only if you are in core99 (special channel) or whatever you want to call it so as to avoid duplication.

Let's move on to the actual guide on how to solve this problem:
First of all you have to bring into core99 all village indexes or any other map where you want players to be able to collect their items / yang from the offline store safe.

Let's move on to the actual guide on how to solve this problem:

  1. <li data-xf-list-type="ol">First of all you have to bring into core99 all village indexes or any other map where you want players to be able to collect their items / yang from the safebox of offlineshop. <li data-xf-list-type="ol">Follow the tutorial of this file:

If anyone has a better solution to fix this problem I would be happy if you shared it with all of us thanks!
Metin2 Sunucularında Ikarus Offline Shop Kopyalanması Sorunu ve Çözümü
Metin2 özel sunucuları geliştirme sürecinde geliştiricilerin karşılaştığı yaygın sorunlardan birisi, Ikarus offline shop sisteminin kopyalanmasıdır. Bu durum, sunucu güvenliği ve oyun içi ekonomi açısından ciddi riskler taşır. Bu makalede, Ikarus offline shop sisteminde yaşanan kopyalama sorununa dair detaylara değinerek, C++ tabanlı bir çözüm sunacağız. Ayrıca, yalnızca gösterim amaçlı olarak kopyalama yöntemi de ele alınacaktır.

Ikarus Offline Shop Nedir?
Ikarus offline shop, oyuncuların internete bağlı olmadan satın alma yapabildiği, Metin2 özel sunucularında popüler olan bir sistemdir. Bu sistem sayesinde oyuncular, belirli eşyaları veya para birimlerini internete bağlı olmadan alabilirler. Ancak bu sistemin bazı güvenlik açıkları bulunabilir.

Kopyalama Nasıl Gerçekleşir?
Genellikle kopyalama işlemi, sunucu tarafında yapılan doğrulama eksiklikleri nedeniyle oluşur. Örneğin, bir oyuncu aynı satın alma işlemini birden fazla kez gerçekleştirdiğinde, sunucu bu işlemleri yeterince kontrol etmezse eşya kopyalaması meydana gelebilir. Bu tür açıklar, C++ kaynak kodunda eksik doğrulamalarla ortaya çıkar.

C++ Tabanlı Güvenlik Çözümü[/CHANNEL][/BR]Sunucu tarafında, her satın alma işleminin benzersiz bir ID ile kayıt edilmesi sağlanmalıdır. Bu ID, veritabanında bir anahtar görevi görür ve tekrarlanan işlemlerde engelleme sağlar. Aşağıdaki gibi bir kontrol sistemi geliştirilebilir:

1. İşlem ID Kontrolü
Her satın alma işlemi için benzersiz bir ID üretilmeli ve bu ID veritabanında kontrol edilmelidir. Aynı ID ile yapılan işlemler reddedilmelidir.

2. Oyuncu Envanter Kontrolü
Satın alma işleminden sonra, envanterdeki eşya sayısı kontrol edilmeli ve beklenenden fazla eşya varsa işlem iptal edilmelidir.

3. Sunucu Log Kayıtları
Tüm işlemler loglanmalı ve şüpheli durumlarda analiz edilmelidir. Bu sayede kopyalama girişimleri daha erken tespit edilebilir.

Kopyalama Yöntemi (Yalnızca Gösterim Amaçlı)
Not: Aşağıdaki yöntem sadece eğitim ve güvenlik testi amaçlıdır. Gerçek sunucularda kullanılması yasaktır.

1. Paket Fırlatma
Oyuncu, aynı satın alma paketini tekrar tekrar göndererek sunucudan yanıt almayı deneyebilir. Eğer sunucu bu paketleri yeterince kontrol etmiyorsa, eşya tekrar eklenir.

2. Zamanlama Saldırısı
Oyuncu, satın alma işlemi sırasında zamanlamayı değiştirerek sunucunun işlem sırasını bozabilir. Bu da kopyalama olasılığını artırır.

Sonuç
Metin2 özel sunucularında Ikarus offline shop sistemi güçlü bir altyapı gerektirir. Geliştiriciler, C++ dilinde güvenli ve kontrollü kodlama yaparak bu tür güvenlik açıklarını önleyebilirler. Sunucu güvenliği için düzenli kod incelemesi, log analizi ve test süreçleri oldukça önemlidir.

Kaynak Kod Paylaşımı


Referanslar
Metin2 sunucu geliştirme kaynakları, C++ güvenlik önerileri, Ikarus offline shop yapılandırması.


Solution to Ikarus Offline Shop Duplication Issues in Metin2 Servers
One of the common issues encountered by developers during Metin2 private server development is the duplication problem within the Ikarus offline shop system. This issue poses serious risks in terms of server security and in-game economy. In this article, we will discuss details regarding the duplication issue in the Ikarus offline shop system and provide a solution based on C++. Additionally, a duplication method will be presented for demonstration purposes only.

What is Ikarus Offline Shop?
The Ikarus offline shop is a popular system in Metin2 private servers that allows players to make purchases without being connected to the internet. Thanks to this system, players can obtain certain items or currencies even while offline. However, this system may contain some security vulnerabilities.

How Does Duplication Occur?
Duplication often occurs due to insufficient validation on the server side. For example, if a player repeats the same purchase multiple times and the server does not adequately check these transactions, item duplication may occur. These vulnerabilities arise from incomplete validations in the C++ source code.

C++ Based Security Solution
On the server side, every purchase transaction should be recorded with a unique ID. This ID serves as a key in the database and prevents repeated transactions. A control system like the following can be developed:

1. Transaction ID Check
A unique ID must be generated for each purchase and checked against the database. Any subsequent transactions with the same ID should be rejected.

2. Player Inventory Check
After a purchase, the number of items in the inventory should be verified. If more items than expected are present, the transaction should be canceled.

3. Server Log Records
All transactions should be logged and analyzed for suspicious activity. This helps detect duplication attempts earlier.

Duplication Method (For Demonstration Only)
Note: The following method is for educational and security testing purposes only. It is forbidden to use it on live servers.

1. Packet Flooding
A player may attempt to resend the same purchase packet multiple times to receive a response from the server. If the server does not validate these packets properly, the item may be added again.

2. Timing Attack
By manipulating the timing during a purchase, a player might disrupt the server's transaction order, increasing the likelihood of duplication.

Conclusion
The Ikarus offline shop system in Metin2 private servers requires a robust infrastructure. Developers can prevent such security vulnerabilities by coding securely and with proper validation in C++. Regular code reviews, log analysis, and testing processes are essential for server security.

Source Code Sharing


References
Metin2 server development resources, C++ security recommendations, Ikarus offline shop configuration.
 

Şuan Bu Konuyu Görüntüleyen Kullanıcılar (Toplam : 0, Üye : 0, Misafir : 0)

Benzer konular

Geri
Üst Alt